Microsoft Here S How To Shield Your Windows Servers Against This Credential Stealing Attack
The PetitPotam take on the NTLM Relay attack was discovered last week by French security researcher Gilles Lionel, as first reported by The Record. The tool Lionel posted can “coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw function,” he explains. In other words, the attack can make a remote Windows server authenticate with an attacker and share Microsoft NTLM authentication credentials and certificates. Microsoft notes that PetitPotam “is a classic NTLM Relay Attack” that it describes in a 2009 security advisory, which it says “can potentially be used in an attack on Windows domain controllers or other Windows servers....